CVE-2023-41179
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.
Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.25%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CISA KEV — explotada activamente
- Añadida al catálogo: 21/9/2023
- Plazo de remediación: 12/10/2023
- Uso conocido en ransomware: Unknown
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 %
AV:N con PR:H indica acceso remoto a consola administrativa; CWE-94 (code injection) permite ejecución arbitraria. T1210 por servicios remotos que requieren privilegios previos; T1059 por ejecución de comandos explícita en descripción.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (3)
CWE
- CWE-94
- CWE-94
Referencias
- https://jvn.jp/en/vu/JVNVU90967486/
- https://success.trendmicro.com/jp/solution/000294706
- https://success.trendmicro.com/solution/000294994
- https://jvn.jp/en/vu/JVNVU90967486/
- https://success.trendmicro.com/jp/solution/000294706
- https://success.trendmicro.com/solution/000294994
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41179
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-41179",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-41179",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-25T14:33:08.513391Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "security@trendmicro.com",
"affectedData": [
{
"vendor": "Trend Micro, Inc.",
"product": "Trend Micro Apex One",
"versions": [
{
"status": "affected",
"version": "2019 (14.0)",
"lessThan": "14.0.0.12380",
"versionType": "semver"
}
]
},
{
"vendor": "Trend Micro, Inc.",
"product": "Trend Micro Apex One",
"versions": [
{
"status": "affected",
"version": "SaaS",
"lessThan": "14.0.12637",
"versionType": "semver"
}
]
},
{
"vendor": "Trend Micro, Inc.",
"product": "Trend Micro Worry-Free Business Security",
"versions": [
{
"status": "affected",
"version": "10.0 SP1",
"lessThan": "10.0 SP1 Build 2495",
"versionType": "semver"
}
]
},
{
"vendor": "Trend Micro, Inc.",
"product": "Trend Micro Worry-Free Business Security Services",
"versions": [
{
"status": "affected",
"version": "SaaS",
"lessThan": "6.7.3578 / 14.3.1105",
"versionType": "semver"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*"
],
"vendor": "trendmicro",
"product": "apex_one",
"versions": [
{
"status": "affected",
"version": "2019"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*"
],
"vendor": "trendmicro",
"product": "worry-free_business_security",
"versions": [
{
"status": "affected",
"version": "10.0"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:trendmicro:worry-free_business_security_services:-:*:*:*:saas:*:*:*"
],
"vendor": "trendmicro",
"product": "worry-free_business_security_services",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:saas:*:*:*"
],
"vendor": "trendmicro",
"product": "apex_one",
"versions": [
{
"status": "affected",
"version": "2019"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2023-09-19T14:15:21.343",
"references": [
{
"url": "https://jvn.jp/en/vu/JVNVU90967486/",
"tags": [
"Third Party Advisory"
],
"source": "security@trendmicro.com"
},
{
"url": "https://success.trendmicro.com/jp/solution/000294706",
"tags": [
"Broken Link"
],
"source": "security@trendmicro.com"
},
{
"url": "https://success.trendmicro.com/solution/000294994",
"tags": [
"Broken Link"
],
"source": "security@trendmicro.com"
},
{
"url": "https://jvn.jp/en/vu/JVNVU90967486/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://success.trendmicro.com/jp/solution/000294706",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://success.trendmicro.com/solution/000294994",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41179",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.\r\n\r\nNote that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el módulo de desinstalación AV de terceros contenido en Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security y Worry-Free Business Security Services podría permitir a un atacante manipular el módulo para ejecutar comandos arbitrarios afectando la instalación. Tenga en cuenta que un atacante primero debe obtener acceso a la consola administrativa en el sistema de destino para poder aprovechar esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T06:20:55.260",
"cisaActionDue": "2023-10-12",
"cisaExploitAdd": "2023-09-21",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "625B375C-C25B-4739-BD1A-BD2969CB3AF6"
},
{
"criteria": "cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:saas:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8FA15535-6AC8-4062-BE7B-CD545B7516E2"
},
{
"criteria": "cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFCE8717-85D2-4F4F-91DF-C6DA341C4E19"
},
{
"criteria": "cpe:2.3:a:trendmicro:worry-free_business_security_services:-:*:*:*:saas:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25F873F7-FC62-4234-99EE-E3BDEBB36C2A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@trendmicro.com",
"cisaRequiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
"cisaVulnerabilityName": "Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability"
}